Go Task 隱私政策
Version: 1.0
生效日期: 2026-09-15
Governing Language: 中文(繁體)
管轄法律: 《個人資料(私隱)條例》Cap 486(下稱「PDPO」)、香港特別行政區法律
語言版本:本文件同時提供中文及英文版本。如中英文版本有任何歧異或不一致,概以中文版本為準;英文版本僅供參考便利之用。
序言
本《Go Task 隱私政策》(下稱「本政策」)說明 Go Task 任務懸賞撮合平台(下稱「本平台」、「Go Task」)如何收集、使用、儲存、共享及保護閣下之個人資料。
本政策應與《Go Task 平台用戶守則與免責聲明》一併閱讀,二者構成閣下與本平台之間完整協議。
本政策依照 PDPO 保障資料原則(Data Protection Principles,DPP) 1-6 之要求草擬,並參考 PCPD AI Guidance 2021(個人資料私隱專員公署人工智能指引)之透明度、解釋權與 appeal 權原則。
1. 平台運營者(Data Controller / 資料使用者)聲明
運營主體: WECAN DESIGN COLLECTIVE LIMITED(香港註冊有限公司)
聯絡電郵: wecangotask@gmail.com
用途範圍: 資料查閱、修正、刪除、客戶服務、AI appeal 申訴
如閣下對本平台之個人資料處理有任何疑問,可向香港個人資料私隱專員公署(PCPD)查詢:
2. 收集之個人資料類別
本平台收集之個人資料分為以下幾類:
2.1 註冊時必需資料
- 電郵地址
- 密碼(經單向加密儲存,平台無法直接讀取明文)
- 顯示名稱(可化名,但不得冒充他人)
- 電話號碼(香港 +852 格式)
- 出生日期 / 年齡(用於 18+ 門檻驗證)
- 性別
- 正面相片(用作頭像 + 識別,見《用戶守則》第 25 條)
2.2 活體驗證階段資料(即時刪除)
- 眨眼 / 微笑動作 frame:純粹作即時 AI 真人核實,驗證成功後即時從媒體儲存永久刪除,絕不留底
- 失敗之 retry frame 於當日 23:59 HKT 前自動清理
2.3 系統自動生成識別碼
- 用戶代碼(格式如 USER-XXXX):公開可見,僅作識別用途,無法逆向關聯個人資料
- 活體識別碼:用作真人身份去重之單向加密短字串(無法還原為人臉資料)
- 內部用戶識別號:平台內部唯一識別碼
2.4 任務及行為資料
- 已刊登 / 已接受之任務內容
- 任務聊天記錄
- 任務相片(完工照、催款備忘錄憑證等)
- 評分及評分歷史紀錄(最近 5 次評分滾動)
- 信用度分數
- 違規紀錄(包括違規累計次數、警告次數、封鎖標記、凍結期限等)
2.5 技術 / 裝置資料
- 裝置型號、作業系統版本
- IP 地址(用於反 Brigade、反多帳號)
- App 版本及使用之語言設定
- Firebase Analytics 收集之匿名 usage data(不含個人身份識別)
- Push notification token(用於通知傳送)
2.6 GM 審計紀錄
- 所有 GM 動作均寫入 管理員審計日誌(包含執行 GM 之識別、被影響用戶、動作類型、原因、時間戳等)
3. DPP1 — 個人資料之收集目的
依 PDPO DPP1(Purpose & Collection),本平台收集個人資料僅用於以下五大目的:
- 身份核實:電話 + 活體驗證,確保用戶為真人並滿 18 歲
- 任務撮合:賞金人與任務獵人之配對、聊天溝通、結算流程
- 信用度評估:評分、棄單偵測、新手保護、Sliding Window 計算
- 安全與防偽:反詐騙、反洗版、反 Brigade、AI 違規偵測
- 法律合規:遵守 PDPO、PCPD AI Guidance、香港其他法例及執法請求
收集之資料不超出達成上述目的所必需之程度(資料最小化原則)。
4. DPP3 — 個人資料之使用限制
依 PDPO DPP3(Use of Personal Data),本平台:
- 不會將閣下之個人資料用於收集時所披露目的以外之任何用途;
- 不會出售、出租或交換閣下之個人資料予任何第三方;
- 不會將閣下之臉部 frame 或聊天訊息主動上傳至任何第三方 LLM。
5. DPP4 — 個人資料之安全保護措施
依 PDPO DPP4(Security),本平台承諾採取合理及業界認可之安全措施,保護閣下之個人資料免遭未經授權訪問、處理、刪除、遺失或使用。
5.1 技術措施(概述)
- 採用業界標準之傳輸層加密保護用戶與平台之間之通訊
- 用戶密碼經單向加密儲存,平台無法讀取明文密碼
- 嚴格之身份驗證及授權機制,確保用戶只可訪問其授權範圍內之資料
- 敏感資料採取額外保護措施(包括但不限於加密、單向 hash、訪問日誌)
5.2 程序措施
- 系統管理員(GM)訪問用戶資料須具備合理理由(爭議調解、合規檢查、安全應對)
- 所有 GM 動作均留底審計,供必要時審查
- GM 不會於無合理需要時訪問用戶私人通訊內容
5.3 局限性聲明
互聯網傳輸無法 100% 保證絕對安全。本平台已採取符合業界合理標準之保護措施,但不能保證絕對防止所有未經授權之入侵。
如本平台發現重大資料外洩事件:
- 將於合理時間內透過 in-app 通知及 email 通知受影響用戶
- 必要時依法向香港個人資料私隱專員公署(PCPD)或執法機關報告
- 啟動內部資料外洩應變程序
6. DPP6 — 用戶資料權利(存取、修正、刪除)
依 PDPO DPP6(Access & Correction),閣下對本平台所持有之個人資料享有以下法定權利:
6.1 資料存取權(Data Access)
閣下可:
- 隨時於 App 內「個人資料及設定」查閱大部分個人資料
- 透過 email 至 wecangotask@gmail.com 提交完整 Data Access Request
- 平台須於法定 40 天內或合理較短期限內回應
6.2 資料修正權(Data Correction)
如閣下發現本平台持有之個人資料有錯誤或過時:
- 大部分資料可於 App 內「個人資料及設定」自行修正
- 部分鎖定欄位(如電話、正面相、活體驗證相關欄位、信用度等)須透過 email 提出書面理由,GM 審批後手動處理
- SLA: 30 工作日內回覆
6.3 資料刪除權(Data Erasure / Right to Be Forgotten)
閣下有權:
例外(平台可保留之資料):
- 違法 / 違規任務證據按《用戶守則》第 30 條保留 3 年
- 法律 / 合規必須保留之資料(稅務、AML、執法請求等)按相關法定保留期保留
- 為防詐騙之最低限度識別碼(電話號碼黑名單 + 正面相之單向 hash,不可還原為原始影像)將保留至該防詐騙目的不再需要為止
資料保留期一覽:
| 資料類別 | 保留期 |
|---|
| 帳號基本資料(電郵、電話、顯示名稱、DOB、性別、頭像) | 帳號存續期間;刪除帳號後 30 日內清除 |
| 活體驗證 frame | 驗證成功即時刪除;失敗 retry frame 於當日 23:59 HKT 前清理 |
| 任務內容、聊天記錄、任務相片 | 帳號存續期間;刪除後 30 日內清除(涉違規者除外) |
| 違法 / 違規任務證據 | 依《用戶守則》第 30 條保留 3 年 |
| 防詐騙最低限度識別碼(電話黑名單 + 正面相單向 hash) | 保留至防詐騙目的不再需要為止 |
| 法律 / 合規必須保留之資料(稅務、AML、執法請求) | 依相關法定保留期 |
| GM 審計日誌 | 依內部合規政策保留 |
6.4 反對 AI 自動化決策權
詳見第 10 節 AI 透明度與 appeal 權。
7. 個人資料之儲存地點與跨境傳輸
本平台採用 Google Cloud 平台之雲端基建。閣下之個人資料儲存及處理於以下區域:
| 用途 | 儲存區域 |
|---|
| 資料庫 | 亞洲區(以台灣機房為主) |
| 後台處理服務(包括 AI 違規偵測) | 美洲區(以美國機房為主) |
| 推送通知、跨平台服務 | 第三方提供商(Apple、Google)之全球網絡 |
閣下使用本平台即代表同意:
- 個人資料跨境傳輸至上述區域及第三方服務供應商
- 上述地點之資料保護法律標準可能與香港不同
- 本平台已盡商業合理努力選擇符合業界加密及保護標準之服務供應商
- 本平台不會將閣下個人資料主動傳輸至中國大陸或其他司法管轄區(除非該用戶身處該地)
PCPD 提醒:PDPO Section 33(跨境資料傳輸限制條款)目前尚未啟用,但本平台主動以透明度原則披露上述資訊。
8. 第三方服務披露
本平台之運作依賴以下第三方服務,各自有獨立之私隱政策:
| 服務 | 提供者 | 收集 / 處理之資料 | 用途 | 傳輸加密 | 是否分享可識別資料 |
|---|
| Firebase | Google LLC | 帳號、資料庫、儲存、通知 | 平台核心基建 | 是(TLS) | 否(僅作平台運營處理) |
| Gemini AI | Google LLC | 任務文本、舉報補充說明 | 違規預審 | 是(TLS) | 否(不含臉部 frame / 聊天私訊) |
| ML Kit Face Detection | Google LLC | 即時面部 frame(on-device) | 活體驗證 | 裝置端處理,不上傳 | 否 |
| Apple 推送通知服務 | Apple Inc. | Push token | iOS 通知傳送 | 是(TLS) | 否 |
| Google Play Services | Google LLC | Push token、SDK runtime | Android 通知 + 安裝環境 | 是(TLS) | 否 |
閣下可透過以下連結查閱該等第三方之私隱政策:
如將來引入其他第三方(如分析平台、支付網關等),本政策將相應更新並通知用戶。
9. Cookie / Analytics / Tracking 聲明
本平台收集匿名 usage data 用於改善服務:
- Firebase Analytics:應用程式啟動、頁面瀏覽、按鈕點擊等 anonymized event
- Firebase Performance:應用程式效能指標、API latency
- Crashlytics(如啟用):應用程式 crash log
上述資料不會用於識別個人身份或進行個人化廣告,並均以匿名化形式收集。
iOS 用戶可透過系統「設定 → 私隱 → 追蹤」全面拒絕跨應用程式追蹤(Apple ATT Framework),本平台尊重該設定。
10. AI 透明度與決策 appeal 權
依 PCPD AI Guidance 2021 之透明度、人手覆核、appeal 原則:
10.1 AI 使用披露
本平台採用之 AI 系統:
- Google Gemini AI — 任務違規預審、舉報補充說明違規偵測
- Google ML Kit on-device Face Detection — 活體驗證之眨眼 / 微笑偵測
- 將來可能引入 AI 任務分類、AI 信用度評估等,屆時另行公告
10.2 用戶之 appeal 權
任何受 AI 自動決策負面影響之用戶(包括但不限於:任務被下架、舉報補充被判違規、活體驗證被拒、警告或扣分等)享有以下權利:
- 24 小時內透過 in-app「申訴中心」或 email 至 wecangotask@gmail.com 提出 appeal
- 須附簡短理由(≤ 200 字)
- GM 須於 7 個工作日內:
- 進行人手覆核(不能單純機械重跑 AI)
- 提供書面回覆(in-app + email)
- 如成立則立即撤銷該 AI 決策並補正資料 / 信用度
- 如不成立則列明理由
10.3 反對全自動化決策
依 PDPO Cap 486 用戶有權反對僅依賴自動化處理(包括 profiling)而對其產生法律或重大影響之決定。本平台之 AI 違規偵測已配套人手覆核機制,符合此項法定要求。
11. DOB(出生日期)專用聲明
依資料最小化原則:
- 閣下之出生日期僅用於確認年齡是否滿足 18+ 門檻
- DOB不會公開予其他用戶
- 即使其他用戶可見閣下之頁面,亦只會見到年齡範圍(例如「25-34」)或無年齡資訊,不顯示確切 DOB
- DOB 不會用於行銷生日推廣等用途(除非另獲明確同意)
12. 未成年人(18 歲以下)
本平台不向 18 歲以下任何人提供服務,並透過:
- 註冊時須自行聲明已年滿 18 歲,系統就出生日期(DOB)作驗證(< 18 即拒絕)
- 如管理員(GM)其後發現用戶未滿 18 歲,有權即時終止其帳號並刪除相關資料
如本平台意外收集到 18 歲以下用戶之資料,將:
- 立即關閉該帳號
- 30 日內從系統中刪除其個人資料(除依法須保留之必要識別碼)
- 通知該用戶(如可聯絡)
如閣下發現有未成年人冒用本平台,請即時聯絡 wecangotask@gmail.com。
13. 隱私政策修訂
本平台保留修訂本政策之權利。重大修訂(包括但不限於變更收集目的、跨境地點、第三方服務、用戶權利等)時:
- 將提前 30 日透過 in-app 公告及 email 通知用戶
- 用戶按「重新同意」按鈕方可繼續使用 — 否則只能行使第 6.3 條「資料刪除權」並退出平台
- 非重大修訂(錯字、表述優化等)將直接於本政策內更新,並同步更新文件頂部之版本號與生效日期
14. 通知與聯絡渠道
對於本政策、個人資料處理或 PDPO 相關之任何疑問、要求或投訴:
接受聲明 / 用戶確認
點擊「我已閱讀及同意《Go Task 隱私政策》全部條款」,即代表閣下:
- ☑ 同意本平台依本政策收集、使用、儲存、跨境傳輸閣下之個人資料;
- ☑ 理解閣下之法定權利(存取、修正、刪除、AI appeal 等);
- ☑ 同意本政策之中文版本為正式約束版本,英文及其他譯本僅供參考,如有歧義以中文為準;
- ☑ 同意接受日後依第 13 條進行之合理修訂(重大修訂另需重新確認)。
Go Task 隱私政策
© 2026 WECAN DESIGN COLLECTIVE LIMITED
保留一切權利。
聯絡電郵: wecangotask@gmail.com
Go Task Privacy Policy
Version: 1.0
Effective date: 2026-09-15
Governing Language: Chinese (Traditional)
Governing law: the Personal Data (Privacy) Ordinance, Cap. 486 (the "PDPO"), and the laws of the Hong Kong Special Administrative Region
Language versions: This document is provided in both Chinese and English. In the event of any discrepancy or inconsistency between the Chinese and English versions, the Chinese version shall prevail; the English version is provided for reference and convenience only.
Preamble
This Go Task Privacy Policy (the "Policy") explains how the Go Task task-bounty matchmaking platform (the "Platform", "Go Task") collects, uses, stores, shares and protects your personal data.
This Policy should be read together with the Go Task Platform User Rules & Disclaimer; together they constitute the entire agreement between you and the Platform.
This Policy is drafted in accordance with the requirements of the PDPO Data Protection Principles (DPP) 1–6, and with reference to the principles of transparency, the right to explanation and the right of appeal set out in the PCPD AI Guidance 2021 (the Guidance on the Ethical Development and Use of Artificial Intelligence issued by the Office of the Privacy Commissioner for Personal Data).
1. Platform Operator (Data Controller / Data User) Statement
Operating entity: WECAN DESIGN COLLECTIVE LIMITED (a Hong Kong registered limited company)
Contact email: wecangotask@gmail.com
Scope of use: data access, correction, deletion, customer service, AI appeals
If you have any questions about the Platform's handling of personal data, you may enquire with the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD):
2. Categories of Personal Data Collected
The personal data collected by the Platform falls into the following categories:
2.1 Data required at registration
- Email address
- Password (stored with one-way encryption; the Platform cannot read the plaintext directly)
- Display name (a pseudonym is allowed, but you must not impersonate others)
- Phone number (Hong Kong +852 format)
- Date of birth / age (used for the 18+ threshold check)
- Gender
- Front-facing photo (used as avatar + identification; see Article 25 of the User Rules)
2.2 Liveness-verification data (deleted immediately)
- Blink / smile action frames: used purely for real-time AI liveness checks; upon successful verification they are permanently deleted from media storage immediately and never retained
- Failed retry frames are automatically cleared before 23:59 HKT the same day
2.3 System-generated identifiers
- User code (e.g. USER-XXXX): publicly visible, used for identification only and cannot be reverse-linked to personal data
- Liveness identifier: a one-way encrypted short string used for de-duplication of real-person identities (cannot be reversed back to facial data)
- Internal user identifier: a unique identifier used internally by the Platform
2.4 Task and behavioural data
- Content of tasks posted / accepted
- Task chat logs
- Task photos (completion photos, payment-demand memo evidence, etc.)
- Ratings and rating history (rolling over the last 5 ratings)
- Credit score
- Violation records (including cumulative violation count, warning count, block flags, freeze periods, etc.)
2.5 Technical / device data
- Device model, operating system version
- IP address (used for anti-brigade and anti-multi-account measures)
- App version and language setting in use
- Anonymized usage data collected by Firebase Analytics (does not contain personally identifying information)
- Push notification token (used for notification delivery)
2.6 GM audit records
- All GM actions are written to the administrator audit log (including the identity of the GM performing the action, the affected user, action type, reason, timestamp, etc.)
3. DPP1 — Purpose of Collection of Personal Data
Under PDPO DPP1 (Purpose & Collection), the Platform collects personal data only for the following five purposes:
- Identity verification: phone + liveness verification, to ensure the user is a real person aged 18 or above
- Task matchmaking: matching of Posters and Hunters, chat communication, and settlement flow
- Credit assessment: ratings, abandonment detection, newcomer protection, sliding-window calculation
- Safety and anti-fraud: anti-fraud, anti-spam, anti-brigade, AI violation detection
- Legal compliance: compliance with the PDPO, the PCPD AI Guidance, other Hong Kong laws and law-enforcement requests
The data collected does not exceed what is necessary to achieve the above purposes (the data-minimisation principle).
4. DPP3 — Restriction on Use of Personal Data
Under PDPO DPP3 (Use of Personal Data), the Platform:
- Will not use your personal data for any purpose other than those disclosed at the time of collection;
- Will not sell, rent or exchange your personal data to any third party;
- Will not proactively upload your facial frames or chat messages to any third-party LLM.
5. DPP4 — Security Measures for Personal Data
Under PDPO DPP4 (Security), the Platform undertakes to adopt reasonable and industry-recognised security measures to protect your personal data against unauthorised access, processing, deletion, loss or use.
5.1 Technical measures (overview)
- Uses industry-standard transport-layer encryption to protect communications between the user and the Platform
- User passwords are stored with one-way encryption; the Platform cannot read plaintext passwords
- Strict authentication and authorisation mechanisms ensure users can only access data within their authorised scope
- Sensitive data is subject to additional protective measures (including but not limited to encryption, one-way hashing, access logging)
5.2 Procedural measures
- System administrators (GMs) must have a reasonable ground to access user data (dispute mediation, compliance checks, security response)
- All GM actions are logged for audit and reviewable when necessary
- GMs will not access the content of users' private communications without a reasonable need
5.3 Limitation statement
Internet transmission cannot be guaranteed to be 100% absolutely secure. The Platform has adopted protective measures meeting reasonable industry standards, but cannot guarantee absolute prevention of all unauthorised intrusion.
If the Platform discovers a serious data breach:
- It will notify affected users within a reasonable time via in-app notification and email
- It will, where necessary, report to the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD) or law-enforcement agencies as required by law
- It will activate internal data-breach response procedures
6. DPP6 — User Data Rights (Access, Correction, Deletion)
Under PDPO DPP6 (Access & Correction), you have the following statutory rights over the personal data held by the Platform about you:
6.1 Right of Data Access
You may:
- Review most of your personal data at any time under "Profile & Settings" in the App
- Submit a full Data Access Request by email to wecangotask@gmail.com
- The Platform must respond within the statutory 40 days or a reasonable shorter period
6.2 Right of Data Correction
If you find that the personal data held by the Platform is inaccurate or out of date:
- Most data can be corrected by yourself under "Profile & Settings" in the App
- Certain locked fields (e.g. phone, front-facing photo, liveness-related fields, credit score, etc.) require a written reason submitted by email, to be handled manually after GM approval
- SLA: reply within 30 business days
6.3 Right of Data Erasure (Right to Be Forgotten)
You have the right to:
- Initiate deletion via the in-app "Delete Account" function
- Or request deletion by email to wecangotask@gmail.com
- The Platform must erase your personal data from its systems within 30 days
Exceptions (data the Platform may retain):
- Evidence of unlawful / violating tasks is retained for 3 years under Article 30 of the User Rules
- Data that must be retained for legal / compliance reasons (tax, AML, law-enforcement requests, etc.) is retained for the relevant statutory retention period
- Minimal identifiers for fraud prevention (phone-number blacklist + a one-way hash of the front-facing photo that cannot be reversed to the original image) are retained until that fraud-prevention purpose no longer requires them
Data Retention Overview:
| Data category | Retention period |
|---|
| Basic account data (email, phone, display name, DOB, gender, avatar) | Duration of the account; erased within 30 days of account deletion |
| Liveness-verification frames | Deleted immediately upon successful verification; failed retry frames cleared before 23:59 HKT the same day |
| Task content, chat logs, task photos | Duration of the account; erased within 30 days of deletion (except where a violation is involved) |
| Evidence of unlawful / violating tasks | Retained for 3 years under Article 30 of the User Rules |
| Minimal fraud-prevention identifiers (phone blacklist + one-way hash of front photo) | Retained until the fraud-prevention purpose no longer requires them |
| Data required for legal / compliance reasons (tax, AML, law-enforcement requests) | The relevant statutory retention period |
| GM audit logs | Retained in accordance with internal compliance policy |
6.4 Right to Object to Automated AI Decision-Making
See Section 10 on AI transparency and the right of appeal.
7. Storage Location and Cross-Border Transfer of Personal Data
The Platform uses the cloud infrastructure of the Google Cloud Platform. Your personal data is stored and processed in the following regions:
| Purpose | Storage region |
|---|
| Database | Asia region (primarily Taiwan data centres) |
| Backend processing services (including AI violation detection) | Americas region (primarily US data centres) |
| Push notifications, cross-platform services | The global networks of third-party providers (Apple, Google) |
By using the Platform you consent to:
- Cross-border transfer of your personal data to the above regions and third-party service providers
- The data-protection legal standards of the above locations may differ from those of Hong Kong
- The Platform has made commercially reasonable efforts to select service providers meeting industry encryption and protection standards
- The Platform will not proactively transfer your personal data to mainland China or other jurisdictions (unless the user is physically located there)
PCPD reminder: PDPO Section 33 (the cross-border data transfer restriction provision) is currently not yet in force, but the Platform proactively discloses the above information in the spirit of the transparency principle.
8. Third-Party Service Disclosure
The Platform's operation relies on the following third-party services, each with its own privacy policy:
| Service | Provider | Data collected / processed | Purpose | Encrypted in transit | Shares identifiable data? |
|---|
| Firebase | Google LLC | Accounts, database, storage, notifications | Core platform infrastructure | Yes (TLS) | No (processed only to operate the Platform) |
| Gemini AI | Google LLC | Task text, report supplementary notes | Violation pre-screening | Yes (TLS) | No (excludes facial frames / private chat) |
| ML Kit Face Detection | Google LLC | Real-time facial frames (on-device) | Liveness verification | Processed on-device, not uploaded | No |
| Apple Push Notification Service | Apple Inc. | Push token | iOS notification delivery | Yes (TLS) | No |
| Google Play Services | Google LLC | Push token, SDK runtime | Android notifications + install environment | Yes (TLS) | No |
You may review these third parties' privacy policies via the following links:
If other third parties (such as analytics platforms, payment gateways, etc.) are introduced in future, this Policy will be updated accordingly and users will be notified.
9. Cookie / Analytics / Tracking Statement
The Platform collects anonymized usage data to improve its services:
- Firebase Analytics: anonymized events such as app launches, page views, button clicks
- Firebase Performance: app performance metrics, API latency
- Crashlytics (if enabled): app crash logs
The above data will not be used to identify individuals or for personalised advertising, and is collected in anonymized form only.
iOS users may fully refuse cross-app tracking via the system's "Settings → Privacy → Tracking" (Apple ATT Framework); the Platform respects that setting.
10. AI Transparency and the Right to Appeal Decisions
In line with the principles of transparency, human review and appeal in the PCPD AI Guidance 2021:
10.1 AI Use Disclosure
The AI systems used by the Platform:
- Google Gemini AI — pre-screening of task violations, violation detection of report supplementary notes
- Google ML Kit on-device Face Detection — blink / smile detection for liveness verification
- AI task classification, AI credit assessment, etc. may be introduced in future, which will be announced separately at that time
10.2 The User's Right to Appeal
Any user adversely affected by an automated AI decision (including but not limited to: a task being removed, report notes being judged as violating, liveness verification being rejected, warnings or point deductions, etc.) has the following rights:
- To file an appeal within 24 hours via the in-app "Appeal Center" or by email to wecangotask@gmail.com
- A brief reason must be attached (≤ 200 characters)
- The GM must, within 7 business days:
- Conduct a human review (not simply re-run the AI mechanically)
- Provide a written reply (in-app + email)
- If the appeal is upheld, immediately reverse the AI decision and restore the data / credit score
- If not upheld, state the reasons
10.3 Objection to Fully Automated Decisions
Under the PDPO (Cap. 486), users have the right to object to decisions that produce legal or significant effects on them based solely on automated processing (including profiling). The Platform's AI violation detection is accompanied by a human review mechanism, meeting this statutory requirement.
11. Special Statement on Date of Birth (DOB)
In line with the data-minimisation principle:
- Your date of birth is used only to confirm whether your age meets the 18+ threshold
- Your DOB will not be disclosed to other users
- Even where other users can see your profile, they will only see an age range (e.g. "25–34") or no age information at all; the exact DOB is not shown
- DOB will not be used for marketing such as birthday promotions (unless separate explicit consent is obtained)
12. Minors (Under 18)
The Platform does not provide services to anyone under 18, and does so by:
- Requiring users to declare at registration that they are at least 18, with the system verifying against the date of birth (DOB) (< 18 is rejected)
- If a GM subsequently discovers that a user is under 18, the Platform has the right to immediately terminate the account and delete the relevant data
If the Platform accidentally collects data of a user under 18, it will:
- Immediately close the account
- Delete the personal data from its systems within 30 days (except identifiers that must be retained by law)
- Notify the user (if contactable)
If you discover that a minor is using the Platform under a false identity, please contact wecangotask@gmail.com immediately.
13. Amendments to the Privacy Policy
The Platform reserves the right to amend this Policy. In the event of a material amendment (including but not limited to changes to collection purposes, cross-border locations, third-party services, user rights, etc.):
- Users will be notified 30 days in advance via in-app announcement and email
- Users must press the "Re-consent" button before they can continue using the Platform — otherwise they may only exercise the "Right of Data Erasure" under Section 6.3 and leave the Platform
- Non-material amendments (typos, wording improvements, etc.) will be updated directly in this Policy, with the version number and effective date at the top of the document updated accordingly
14. Notices and Contact Channels
For any questions, requests or complaints regarding this Policy, personal-data handling or the PDPO:
- Preferred: email to wecangotask@gmail.com
- Third-party complaint channel: Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD)
Acceptance Statement / User Confirmation
By clicking "I have read and agree to all terms of the Go Task Privacy Policy", you:
- ☑ Agree that the Platform may collect, use, store and transfer across borders your personal data in accordance with this Policy;
- ☑ Understand your statutory rights (access, correction, deletion, AI appeal, etc.);
- ☑ Agree that the Chinese version of this Policy is the formal binding version, and that the English and other translations are for reference only; in case of ambiguity, the Chinese version prevails;
- ☑ Agree to accept reasonable future amendments made under Section 13 (material amendments require separate re-confirmation).
Go Task Privacy Policy
© 2026 WECAN DESIGN COLLECTIVE LIMITED
All rights reserved.
Contact email: wecangotask@gmail.com